Skip to content
KitploitKITPLOIT
أدواتالمدونة
Log in
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
security-research — PoCs & write-ups for CVEs I reported (coordinated disclosure; published + patched only) | Kitploit
أدوات/GitHubGitHub/pig-tail/security-research
Vulnerability AnalysisExploitationWeb Application ExploitationCurated Resources
GitHubpig-tail/security-research

security-research

PoCs & write-ups for CVEs I reported (coordinated disclosure; published + patched only)

عرض المستودع
112منذ 6 أياملم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.

security-research

Proof-of-concept code and technical write-ups for vulnerabilities I discovered and reported through coordinated disclosure. Every entry here is already public: the vendor advisory is published and a fixed release is available. Nothing under embargo or in draft is included.

The PoCs are verification harnesses, not weaponized exploits: each runs against a local, self-owned instance and proves the defect with a benign sentinel (a marker file, a seeded "secret" record, a policy-evaluation assertion). None of them target third-party systems, and none perform any destructive or persistent action.

— Pig-Tail · Offensive Security Engineer & Vulnerability Researcher · [email protected]

Index

CVE / AdvisoryProjectClass (CWE)SeverityPoC
GHSA-f5m5-jfmq-ghpxSteeltoeOSS/NetCoreToolServiceUnauthenticated RCE via argument injection into 'dotnet new' (CWE-88)Critical✅ runnable
CVE-2026-77312flyto-coreArbitrary file write via unguarded data./file. modules (in (CWE-22)Critical✅ runnable
GHSA-7833-fr7j-v32qGitPythonArbitrary local file content disclosure via [include] direct (CWE-73/CWE-200)High✅ runnable
GHSA-284h-m62q-gf8wGitPythonDormant multi-line git-config values are corrupted into live (CWE-88/CWE-94)High✅ runnable
GHSA-8mcc-hrx5-hvxcGitPythonclone_from()/clone() omit --separate-git-dir from unsafe_git (CWE-22/CWE-73)High✅ runnable
CVE-2026-62263OpenAMOpenAM WebAuthn Java deserialization RCE via ObjectInputFilt (CWE-502)High📄 write-up
CVE-2026-53626glpiArbitrary document read (CWE-639/CWE-862)High📄 write-up
CVE-2026-75606egroupwareAuthenticated SQL injection via col_filter string-key in Base (CWE-89)High✅ runnable
CVE-2026-93537fleetPath traversal in Helm valuesFiles reads outside the bundle (CWE-22/CWE-200)High📄 write-up
CVE-2026-93538fleetCross-tenant BundleDeployment/Secret disclosure via spoofed (CWE-290/CWE-639/CWE-863)High📄 write-up
CVE-2026-49285glpi-agentOS Command Injection in GLPI Agent ToolBox Results export vi (CWE-78)High📄 write-up
CVE-2026-52764glpi-agentMSSQL inventory module executes OS commands with unsanitized (CWE-78)High📄 write-up
CVE-2026-45621glpi-agentMongoDB inventory module allows JavaScript injection via une (CWE-94/CWE-116)High📄 write-up
CVE-2026-46615glpi-agentDatabase inventory modules execute OS commands with unsaniti (CWE-78)High📄 write-up
CVE-2026-40936glpi-agentToolBox plugin can allow unauthenticated path traversal lead (CWE-22/CWE-73)High📄 write-up
CVE-2026-48730glpi-inventory-pluginReflected XSS (CWE-79)High📄 write-up
CVE-2026-75594kirbyAccess to image files and limited access to JSON files outsi (CWE-22)High📄 write-up
CVE-2026-77437kiwitcmsORM lookup-injection in RPC *.filter methods leaks bug-track (CWE-943/CWE-200)High✅ runnable
CVE-2026-77435kiwitcmsAuthenticated SSRF via Bug.details API method (CWE-918/CWE-697)High✅ runnable
CVE-2026-58229mintUnbounded HTTP/1 response-header and chunked-trailer accumul (CWE-770)High✅ runnable
CVE-2026-61699nebula-meshCertificate revocation is never enforced at the mesh: nebula (CWE-299/CWE-672)High📄 write-up
CVE-2026-63202netty-incubator-codec-ohttpBinaryHttpParser: Unauthenticated CPU-exhaustion DoS via inf (CWE-400/CWE-835)High✅ runnable
GHSA-p6gq-j5cr-w38fnodemailerMessage-level raw option bypasses disableFileAccess/disableU (CWE-73/CWE-918)High✅ runnable
CVE-2026-71315nuxtNuxt route rules silently dropped for mixed-case paths, bypa (CWE-178/CWE-863)High✅ runnable
CVE-2026-62375opendjOpenDJ Unbounded VLV offset array allocation → memory-exhaus (CWE-190/CWE-770/CWE-789)High📄 write-up
CVE-2026-62366opendjOpenDJ Unauthenticated stack exhaustion when decoding an LDA (CWE-400/CWE-674)High📄 write-up
GHSA-r9mf-88r7-g6j9proboAccount takeover via OIDC login: the continue redirect hands (CWE-384/CWE-601)High✅ runnable
CVE-2026-76079proboVertical privilege escalation: an organization ADMIN can min (CWE-269/CWE-863)High✅ runnable
GHSA-fj3w-533r-fvf6python-statemachineSCXML reads arbitrary local files when (CWE-22/CWE-200)High✅ runnable
GHSA-r7hw-jx6r-756gsaml2Incomplete fix of CVE-2026-49283: unsigned embedded Response (CWE-287/CWE-347)High✅ runnable
CVE-2026-62989shopperMissing authorization on product variant DeleteAction/Delete (CWE-285/CWE-862)High📄 write-up
CVE-2026-86043skipperOPA body-authz bypass: truncated_body mitigation fails ope (CWE-863)High✅ runnable
CVE-2026-54697cbsshExcessive allocation and integer overflow in DER private-key (CWE-190/CWE-789)Medium📄 write-up
تنزيل الأداة